FORENSIA

THREAT_ACTOR · G0032

Lazarus Group

Also known as: Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet

Profile

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.

MITRE ATT&CK ↗

Techniques

93 ATT&CK techniques attributed to this actor.

T1001.003 Protocol or Service ImpersonationT1005 Data from Local SystemT1008 Fallback ChannelsT1010 Application Window DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1021.001 Remote Desktop ProtocolT1021.002 SMB/Windows Admin SharesT1021.004 SSHT1027.007 Dynamic API ResolutionT1027.009 Embedded PayloadsT1027.013 Encrypted/Encoded FileT1033 System Owner/User DiscoveryT1036.003 Rename Legitimate UtilitiesT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1041 Exfiltration Over C2 ChannelT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1055.001 Dynamic-link Library InjectionT1056.001 KeyloggingT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1070 Indicator RemovalT1070.003 Clear Command HistoryT1070.004 File DeletionT1070.006 TimestompT1071.001 Web ProtocolsT1074.001 Local Data StagingT1078 Valid AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1090.001 Internal ProxyT1090.002 External ProxyT1098 Account ManipulationT1102.002 Bidirectional CommunicationT1104 Multi-Stage ChannelsT1105 Ingress Tool TransferT1106 Native APIT1110.003 Password SprayingT1124 System Time DiscoveryT1132.001 Standard EncodingT1134.002 Create Process with TokenT1140 Deobfuscate/Decode Files or InformationT1189 Drive-by CompromiseT1202 Indirect Command ExecutionT1203 Exploitation for Client ExecutionT1204.002 Malicious FileT1218 System Binary Proxy ExecutionT1218.005 MshtaT1218.011 Rundll32T1485 Data DestructionT1489 Service StopT1491.001 Internal DefacementT1529 System Shutdown/RebootT1542.003 BootkitT1543.003 Windows ServiceT1547.001 Registry Run Keys / Startup FolderT1547.009 Shortcut ModificationT1553.002 Code SigningT1557.001 Name Resolution Poisoning and SMB RelayT1560 Archive Collected DataT1560.002 Archive via LibraryT1560.003 Archive via Custom MethodT1561.001 Disk Content WipeT1561.002 Disk Structure WipeT1564.001 Hidden Files and DirectoriesT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1566.003 Spearphishing via ServiceT1571 Non-Standard PortT1573.001 Symmetric CryptographyT1574.001 DLLT1574.013 KernelCallbackTableT1583.001 DomainsT1583.006 Web ServicesT1584.004 ServerT1585.001 Social Media AccountsT1585.002 Email AccountsT1587.001 MalwareT1588.002 ToolT1588.004 Digital CertificatesT1589.002 Email AddressesT1591 Gather Victim Org InformationT1620 Reflective Code LoadingT1680 Local Storage DiscoveryT1685 Disable or Modify ToolsT1686.003 Windows Host Firewall

Software

26 malware/tools attributed to this actor.

routenetshResponderVolgmerFALLCHILLProxysvcBankshotRATANKBABADCALLHARDRAINTYPEFRAMEKEYMARBLEAuditCredRawDiskWannaCryHOPLIGHTHotCroissantDaclsCryptoisticBLINDINGCANDtrackAppleJeusTAINTEDSCRIBEECCENTRICBANDWAGONThreatNeedleMagicRAT

Related corpus activity

10,444 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Lazarus Group.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,444.